PT-2009-4121 · Unknown · Simple Customer

Ahmadbady

·

Published

2009-05-15

·

Updated

2017-09-29

·

CVE-2009-1637

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions: Simple Customer version 1.3
Description: The issue allows remote attackers to change the admin e-mail address and password without requiring administrative authentication. This can be achieved by modifying the email and password parameters in the profile.php file.
Recommendations: For Simple Customer version 1.3, consider temporarily restricting access to the profile.php file until a patch is available. As a mitigation measure, avoid using the email and password parameters in the profile.php file to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-1637

Affected Products

Simple Customer